A technical report obtained by Computer Weekly reveals that French Gendarmerie cyber-spies compromised the EncroChat network in 2020 using a known 2017 Android exploit, with code copied from GitHub and quality described as a "student project." The disclosure, published August 17, 2026, threatens to reopen thousands of cases across Europe and invalidate convictions based on evidence gathered through methods never made public.
- The French implant exploited CVE-2019-2215 (Bad Binder bug), a use-after-free vulnerability in the Android binder driver rated CVSS 7.8 HIGH per the NVD record.
- The exploit code was copied from public GitHub repositories and adapted to intercept EncroChat messages before end-to-end encryption via API hooking.
- Czech firm Invasys reverse-engineered the implant and found matches with digital evidence submitted across Europe.
- Thousands of UK cases were tried without explanation of the data-acquisition method, classified by French authorities as a national security secret.
The Attack Method: CVE-2019-2215 and the Message "Trampoline"
The technical report from Czech firm Invasys, analyzed by the Sussex Centre for Law and Technology and obtained by Computer Weekly, documents that the French implant relied on CVE-2019-2215, known as the Bad Binder bug. The vulnerability, a use-after-free in Android's binder IPC driver, allowed local privilege escalation to root. According to the NVD record, severity is CVSS 3.1 7.8 HIGH with vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
The exploit code had been publicly available on GitHub for roughly two years, leaving approximately 2.5 billion Android devices vulnerable before the patch became widespread. French technicians copied and adapted it to create a persistent implant on EncroChat phones, which ran Guardian ROM, an Android derivative from the Guardian Project with Off-the-Record messaging.
Interception occurred via API hooking using a technique described as a "trampoline": messages were "hooked" and copied to investigators almost immediately, before the end-to-end encryption process could render them unreadable. This mechanism allowed real-time collection of communications without breaking the encryption itself, bypassing the underlying operating system instead.
Malware Quality: A "Student Project" Without Anti-Forensic Countermeasures
Felix Freiling, professor of forensics at Friedrich-Alexander-Universität Erlangen-Nürnberg (FAU), examined the Invasys report and characterized the implant code as "looks like a student project." The technical reconstruction shows software that was "poorly written, prone to repeated failure, and lacked elementary countermeasures to avoid detection" — missing basic anti-forensic measures that could have hindered reverse engineering.
This lack of sophistication made Invasys's detailed reconstruction possible, which then found digital matches with evidence submitted by French authorities across Europe. The paradox is clear: a nation-state used low-quality open-source code to infiltrate a criminal network, and that very poor quality exposed the method six years later.
Legal Consequences: Thousands of Cases at Risk of Reopening
The UK National Crime Agency's Operation Venetic led to weapons seizures and hundreds of millions of pounds in drugs and cash, based on data extracted from the hacked phones. However, thousands of UK cases were tried and convicted without any explanation of the acquisition method: French authorities had imposed a national security classification on the interception technique.
Matthew Ryder KC, lead counsel in the first UK EncroChat trial, called the revelation a "landmark breakthrough." According to Ryder, "after six years, we may finally know the details of the interception by the French authorities. This will have consequences for ongoing legal arguments and legal principles relating to interception and computer interference."
The case has been stayed for more than two years at the UK Investigatory Powers Tribunal, the body overseeing intelligence and surveillance activities. Publication of the technical method could restart hearings and challenge the validity of the collected evidence.
"We can't simply say 'we trust the data' while not being able to do proper research into the manner of obtaining it. That is vital to providing suspects with fair trials. We have been asking for that information for six years." — Justus Reisinger, Dutch criminal defense lawyer, European defense legal team
The European Context: EncroChat as a Case Study in State Surveillance
EncroChat operated a targeted commercial model: phones with a customized OS, end-to-end encrypted messaging, automatic deletion within 14 days, and costs exceeding $1,000 for a six-month contract. Launched in 2014 with roughly 50 initial clients, the network grew to tens of thousands of users across Europe, predominantly associated with organized crime but also including legitimate professionals concerned about privacy.
The revelation of the French method raises questions beyond the single case. Justus Reisinger, a Dutch criminal defense lawyer, stated the information will be "vital for EncroChat trials and appeals," emphasizing that the defense cannot function without knowing the technical methods of evidence acquisition. The information asymmetry between prosecution and defense — amplified by the method's classification as a national secret — has characterized years of European jurisprudence on this case.
The dossier does not specify whether the full Invasys report will be made public or remain restricted to legal defenses. It also does not indicate whether French authorities will confirm or deny the technical reconstruction from the reverse engineering.
Why This Matters
The EncroChat case demonstrates that "security through obscurity" fails when reverse engineering reconstructs state surveillance methods, even years later. For cybersecurity firms, the key takeaway is that state operators can resort to unsophisticated open-source code, with unintended consequences for operational secrecy.
For the legal sector, the disclosure exposes the limits of a system that allowed convictions based on evidence of unverifiable provenance. The tension between investigative effectiveness and the rule of law remains open: when authorities use questionable-quality malware to catch criminals, suspects' rights to a fair trial risk being structurally compromised.
For encrypted technology providers, the episode highlights that vulnerability can reside in the underlying operating system rather than the messaging application. End-to-end encryption does not protect if the device is already compromised at the root level.
FAQ
What is the difference between the EncroChat hack and other surveillance cases like Pegasus?
The EncroChat case is distinct because the implant was installed on devices via a generic Android exploit, not through a specific application like NSO Group's Pegasus. Additionally, the method was revealed years later through independent reverse engineering, not via journalistic investigation of a commercial vendor.
Why is the GitHub-sourced code relevant to the trials?
The code's origin matters because it shows the interception method was not based on sophisticated proprietary technology but on a publicly available exploit. This raises questions about proportionality and operational secrecy, central elements in legal arguments over evidence validity.
What happens now with the case at the Investigatory Powers Tribunal?
The dossier does not document a specific date for hearings to resume. The case has been adjourned for more than two years, and publication of the technical report could provide grounds to restart examination of the legality of police tactics in the EncroChat context.
Sources
- https://www.computerweekly.com/news/366649396/Revealed-Cyber-spies-used-malware-from-GitHub-to-hack-EncroChat-cryptophone-network
- https://thecyberwire.com/podcasts/daily-podcast/2617/notes
- https://securityaffairs.com/197728/breaking-news/security-affairs-newsletter-round-591-by-pierluigi-paganini-international-edition.html
- https://www.indesignmarketingservices.com/revealed-cyber-spies-used-malware-from-github-to-hack-encrochat-cryptophone-network/
- https://securityaffairs.com/197728/breaking-news/security-affairs-newsletter-round-591-by-pierluigi-paganini-international-edition.html?amp
- https://nvd.nist.gov/vuln/detail/CVE-2019-2215
- https://www.wilderssecurity.com/threads/guardian-rom-secure-android-os.348416/
- https://securityaffairs.com/197610/security/polands-cert-warns-of-active-exploitation-of-critical-zimbra-collaboration-suite-flaw.html
- https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/
- https://www.securityweek.com/300000-wordpress-sites-potentially-exposed-to-hacking-due-to-form-plugin-flaw/
Information verified against cited sources and current as of publication.